License editions: To understand the applicable license editions, see Plans & Pricing.
Overview
If you want to scan files before you restore them, you must enable the Restore Scan Settings. When enabled, you see an additional Restore Scan section in the restore window where you can select the options related to the file scan.
❗Important: Restore Scan is supported for Endpoints, File Server, NAS,VMware virtual machines (Sandbox Recovery), Azure Virtual Machines and AWS Workloads - EC2 and EBS Volume restores.
Here are the scanning options for Restore scans:
Quick Scan: A faster option with minimal impact on restore performance, ideal for regular use. It improves scan time by focusing on specific file types commonly associated with malware and recently modified files.
❗Important:
By default, the Quick Scan option is enabled.
Deep Scan: A comprehensive option that scans all file types for thorough detection. It is best suited for post-breach restores or when malware is suspected. Due to its exhaustive nature, Deep Scan may take longer, particularly for large backups.
We recommend you retain the default Quick Scan option. However, for a Deep scan, select All Files.
If you enforce the scan during data restore, administrators will not be able to disable the scan while initiating the restore. This ensures that the data restored is free of malware and viruses.
If you enforce the scan, end users will not see a message or notification stating that the data is being scanned before restoring.
Procedure
From the Druva Cloud Platform Console, go to Global Navigation menu -> Ransomware Recovery.
On the left pane, click the Restore Scan -> Settings tab.
In the Settings section, click Edit.
Toggle the Antivirus Scan button in the Scan Settings section to allow administrators to view the Restore Scan panel in the Restore window.
Toggle the File Hash Scan button in the Scan Settings section to enable file scan during restore for custom file hashes from the IOC library.
Select the checkbox to allow the scan with Druva-published IOC sets. This is applicable only if you have a Premium Security license. By default, it is enabled.
Toggle the Quick Scan button in the Scan Optimisation Setting section to enable Restore scan for selective files.
The Quick Scan option scans selective files such as those modified and created in the last 30 days, files smaller than 100 MB file size, and excludes specific file extensions that are not malware-prone - for example, jpeg, jpg, png, gif, bmp, mp3, mp4, log.
The Deep Scan option scans all files (up to 1 GB file size) without any exclusions for comprehensive coverage.
By default, the Quick Scan option is enabled.
Under the Override Scanning section, select if you want to show administrators and end users the ability to disable restore and quick scan settings during a restore operation. This applies to Enterprise Workloads (File Server and NAS) and Endpoints.
Note that a restore activity takes more time than usual when scanning is enabled.
Under the Override Scanning section, select the Skip Antivirus Scan during Device Replacement check box to disable the antivirus scan check before restoring data to the new device. By default, this option is deselected. Then, click Save. This applies to Endpoints only.
Administrators are notified via multiple channels when malicious files are identified and blocked during a restore scan:
Email Alerts: When malicious files are found, an automated warning alert is generated and emailed to all subscribed administrators.
Alerts Page: Comprehensive alert details are available for viewing on the Alerts page within the Druva console.
Audit Trails: Scan job results and activities can be tracked in the Audit Trails section by filtering for the specific Service - Ransomware Recovery and Activity Type - Restore Scan job created.
💡 Tip
We recommend that you refrain from selecting this option and allow an antivirus scan during device replacement to ensure that the restored data is safe and secure.
To receive updates regarding malicious files blocked during restore scans, ensure that your account is subscribed to email alerts.
❗ Important
The System Settings are not scanned for antivirus.
Restore Scan is only available for Endpoints, File Server, NAS, VMware virtual machines (Sandbox Recovery), Azure Virtual Machines, and AWS Workloads - EC2 and EBS restores.
FAQ's for Restore Scan
Does File Hash Scan impact performance more than enabling Antivirus scan alone?
File Hash Scan does not significantly impact performance beyond what Antivirus scan already does. Both scans happen together during the restore process, so enabling File Hash Scan adds minimal overhead to the existing antivirus scanning. For most use cases, the default Quick Scan provides good protection with minimal performance impact.
Should I use Druva's Published IOC Sets or create my own?
We recommend using both for comprehensive protection:
Druva Published IOC Sets: Curated from widely trusted sources like CISA advisories, updated periodically with new threats. Requires Premium Security license.
Custom IOC Sets: Let you add specific file hashes (up to 2000 SHA1, SHA-256, or MD5) relevant to your organization's specific threat landscape.
This layered approach gives you both broad industry threat coverage and targeted protection for your environment.
Can Restore Scan be turned off immediately?
Yes, Restore Scan can be turned off immediately — there is no waiting period between enabling and disabling it. However, note the following:
If your administrator has mandated scanning during restore activities, you will not be able to disable it at the restore level.
The ability to disable scans depends on whether the Override Scanning option is enabled in the Restore Scan Settings.
What is the recommended maximum file size for Scan Optimization?
The default maximum file size is 100 MB, and you can set it between 100 MB and 1024 MB (1 GB). The 100 MB default strikes a good balance — most malicious files are smaller, so you get solid protection without scanning large media files or databases that rarely contain threats.
📝Note: Restore scan is not supported for files beyond 1 GB anyway.

